Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,657GitHub PoC 14,424VulnCheck XDB 8,773Nuclei 4,340Metasploit 3,485✓ verified onlyrecentpopularrisk
22,657 exploits
Referência
CVE-2021-47907
Rocket LMS 1.1 Persistent Cross-Site Scripting via Support Tickets
33RISK
open ↗Referência
CVE-2006-5190
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers t
23RISK
open ↗Referência
CVE-2006-5190
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers t
23RISK
open ↗Referência
CVE-2006-5190
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers t
23RISK
open ↗Referência
CVE-2026-78140
Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engine
33RISK
open ↗Referência
CVE-2026-78115
SourceCodester Class and Exam Timetabling System User Account Update edit_user_account.php improper authorization
33RISK
open ↗Referência
CVE-2026-10053
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
41RISK
open ↗Referência
CVE-2026-78112
itsourcecode Hospital Management System Project in PHP viewservicetype.php sql injection
33RISK
open ↗Referência
CVE-2026-77116
Brave Popup Builder < 0.8.6 - Subscriber+ Unpublished Popup Disclosure via Preview
33RISK
open ↗Referência
CVE-2026-77001
Social Login & Sharing buttons with Analytics By SoClever <= 1.2.0 - Unauthenticated Authentication Bypass
48RISK
open ↗Referência
CVE-2018-25302
Allok AVI to DVD SVCD VCD Converter 4.0.1217 Buffer Overflow SEH
41RISK
open ↗Referência
CVE-2026-7127
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
33RISK
open ↗Referência
CVE-2026-7118
code-projects Employee Management System cancel.php sql injection
33RISK
open ↗Referência
CVE-2026-7042
666ghj MiroFish REST API Endpoint __init__.py create_app missing authentication
33RISK
open ↗Referência
CVE-2026-7041
666ghj MiroFish Werkzeug Debugger PIN console information disclosure
33RISK
open ↗Referência
CVE-2026-7038
tufantunc ssh-mcp Command Line index.ts insufficiently protected credentials
33RISK
open ↗Referência
CVE-2026-7037
Totolink A8000RU CGI cstecgi.cgi setVpnPassCfg os command injection
48RISK
open ↗Referência
CVE-2026-7035
Tenda FH1202 httpd WrlclientSet fromWrlclientSet stack-based overflow
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.